Chinese hackers are ramping up attacks after integrating DeepSeek and other open-source artificial intelligence models into their operations, highlighting attackers’ ability to leverage basic AI tools to hit targets abroad.
State-affiliated cyber groups more than doubled the amount of attacks they carried out since they began delegating mundane tasks to AI and using it to develop advanced malicious software, according to TeamT5, a Taiwanese re
search firm. Researchers said it wasn’t always possible to identify the AI model they used, but in general DeepSeek’s offerings are popular with hackers in the country because of its high performance and ability to be customized.
Anxieties among US national security officials are mounting over the autonomous capabilities of advanced models from Anthropic PBC and OpenAI after a series of high-profile incidents in which they managed to break out of testing environments.
Researchers say experienced Chinese hackers are using far less capable AI to scale up their activities and achieve breakthroughs. While other models produced in the country are more powerful – including Moonshot’s bre
akout Kimi K3 model – hackers are drawn to DeepSeek’s relatively lax cybersecurity barriers and low cost of running, researchers said. They added that they had yet to record an incident involving Kimi K3, which they believe is prohibitively expensive for hackers to run.
Watch More Image Part 2 >>>
“DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said Charles Li, chief analyst at TeamT5. “Western models are highly sought-after but their guardrails are much more strict and require a lot more effort to bypass.”
DeepSeek didn’t respond to a request for comment. Neither China’s Embassy in Washington nor its Ministry of Foreign Affairs responded to messages seeking comment.
Along with a mix of other open-source models, DeepSeek has been adopted throughout multiple stages of an attack, conducting reconnaissance and generating means of attacking vulnerabilities, TeamT5 said. They said in
recent months they’ve obtained scripts and logs showing the model being used by hackers affiliated with the Chinese government throughout their operations.
A group known as Grimfengxi used DeepSeek to create exploit codes. Another group, called Huapi, used a Chinese AI model, which researchers said was likely DeepSeek, to attack an email system of a Taiwanese company. A third, known as Teleboyi, used the platform to collect 1,000 IP addresses from the internet and map a company’s domains.























